Share This Article
From today, 2 August 2026, the EU AI Act becomes enforceable, and yet some of the obligations that dominated every compliance roadmap of the past two years are not the ones that start to bite.
On 27 July 2026, Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, entered into force and amended the AI Act just days before its main application date. The intention, following the Draghi Report and the wider debate on over-regulation, was to simplify. The result is a calendar that few companies have fully absorbed, as we anticipated when the amendments were published in the Official Journal.
Let me be clear about the effect, because the misunderstanding I encounter is remarkably consistent. The Digital Omnibus postponed the most significant compliance obligations, those concerning high-risk AI systems. It did not move the general date of application of the AI Act, which remains today, 2 August 2026. Both statements are true at the same time, and the space between them is where the risk currently sits.
In short
- Enforcement starts on 2 August 2026. The high-risk obligations do not.
- Article 50 transparency applies to almost every business, not only to model providers.
- Customising, retraining or rebranding an AI system can turn a deployer into a provider.
- Annex III high-risk obligations move to 2 December 2027, Annex I to 2 August 2028.
- The practical obstacle is rarely the law. It is that nobody owns AI compliance.
What the EU AI Act 2 August 2026 deadline actually triggers
Three things change today, and at least one of them applies to almost every organisation reading this.
The EU Commission and the AI Office acquire the power to investigate and fine providers of general-purpose AI models, with penalties reaching EUR 15 million or 3% of worldwide turnover.
The transparency obligations under Article 50 become enforceable. I return to these below, because they are the provision that received the least attention and reaches the largest number of businesses.
The penalty framework becomes operative, and national market surveillance authorities can enforce every provision already in force. Sanctions are calibrated on three levels:
- up to EUR 35 million or 7% of global turnover for prohibited practices such as social scoring;
- up to EUR 15 million or 3% for breaches of the other conformity obligations applying to providers and deployers; and
- a lower tier for inaccurate, incomplete or misleading information supplied to notified bodies or national authorities.
Prohibited practices under Article 5 and the AI literacy duty under Article 4 have applied since 2 February 2025. On literacy, the Omnibus softened the requirement: it is now sufficient to adopt measures supporting the development of AI literacy among staff, without having to guarantee a specific level.
Article 50, the obligation that reaches almost every business
From today, anyone supplying systems that interact with people must make the artificial nature of the system recognisable, unless it is already evident from the context. Anyone using emotion recognition or biometric categorisation must inform the individuals concerned. Anyone using AI to generate deepfakes, or texts intended to inform the public on matters of general interest, must say so expressly. A newspaper publishing articles drafted with AI support falls squarely within this.
In practice, the scope is broad: customer service chatbots, voice agents, virtual assistants and avatars, AI-generated images and video, synthetic audio, AI-assisted editorial content.
One exception matters. The watermarking of synthetic content under Article 50, second paragraph, does not apply immediately to systems already placed on the market before 2 August 2026. For those, the obligation runs from 2 December 2026. The human-facing disclosure, however, applies from today. The disclosure is also, by some distance, the least expensive compliance measure in the entire Regulation, which makes its neglect hard to explain to a board.
When a deployer becomes a provider, and the sanctions follow
This is the point I would most like companies to take away, because it is the one that turns an apparently distant regulation into an immediate exposure.
The enforcement powers described above are not a concern only for the large technology companies that build foundation models. Under the AI Act, a deployer can be requalified as a provider. It happens where a company customises an AI system for its own needs, trains or fine-tunes it on its own data, or places it on the market under its own name or trade mark. Substantial modification of a high-risk system produces the same effect.
The consequence is not cosmetic. Requalification moves an organisation from the comparatively light set of duties applying to deployers into the full provider regime, with the documentation, conformity and enforcement exposure that comes with it, and with the penalties referred to above becoming applicable to it.
In practice, this is happening constantly and quietly. A bank fine-tunes a commercial model on its own customer interactions. A retailer white-labels a conversational assistant. A software company embeds a third-party model in its own product and sells it under its brand. Each of these is a candidate for requalification, and in most cases nobody in the organisation has asked the question. It is worth an hour with counsel before a letter arrives, rather than after.
What the Digital Omnibus postponed
- High-risk systems under Annex III – obligations and requirements now apply from 2 December 2027, rather than 2 August 2026. This covers recruitment and employment, credit scoring, education, essential public and private services, biometrics, critical infrastructure, law enforcement, migration and justice.
- High-risk systems embedded in regulated products under Annex I – deferred to 2 August 2028.
- The new prohibition on nudification – from 2 December 2026 it becomes unlawful to place on the market, put into service or use AI systems intended to generate non-consensual sexual or intimate content, or child sexual abuse material. The prohibition responds to the alarm generated by applications capable of producing intimate images from an ordinary photograph of any individual, minors included. The Clothoff case, censured by the Italian Garante, is the obvious reference point.
- National regulatory sandboxes – the deadline for Member States to establish at least one sandbox moves to 2 August 2027.
Alongside the deferrals sit several genuine simplifications. The authorisation to process special categories of personal data for detecting and correcting bias, previously available to providers of high-risk systems, has been extended to deployers of those systems and to providers and deployers of other AI systems and models. The lighter regime for SMEs, covering technical documentation and priority access to sandboxes, now extends to small mid-cap companies. And the notion of safety component, which drives high-risk classification, has been clarified: it captures only systems whose purpose is to prevent or mitigate risks to the health and safety of persons or property, excluding mere user assistance, performance optimisation, service efficiency, automation and quality control.
Expectations of simplification were high. In truth these are careful adjustments rather than a genuine change of pace, which would have been welcome.
Why the postponement helps less than it appears
The high-risk regime is demanding, and it does not assemble itself in a quarter.
Providers of high-risk systems must establish a risk and quality management system, prepare technical documentation demonstrating conformity and allowing the functioning of the system to be traced, retain automatically generated logs, comply with registration duties, ensure human oversight, guarantee transparent operation with adequate information to deployers, and secure appropriate levels of accuracy, robustness and cybersecurity. Deployers must use systems in accordance with the provider’s instructions, ensure supervision of outputs by competent personnel, monitor operation and report risks, and retain the logs under their control. Public law bodies, private entities providing public services, banks and insurers must in addition carry out a fundamental rights impact assessment.
Technical documentation, fundamental rights impact assessments and vendor requalification carry lead times of six to twelve months. On how to structure that exercise, you may find of interest our article on AI risk assessment frameworks and how to map, classify and prioritise risks. Moreover, the inventory of AI systems required for December 2027 is precisely the inventory a supervisory authority may ask to see this year. The first move of an authority is rarely a dawn raid. It is a request for documentation, which costs the regulator almost nothing to send.
So the honest question for any board is simple. Could your organisation produce a complete inventory of the AI it uses, with owners and purposes, within a week?
In my experience, most cannot. The reason is almost never a missing policy.
The real obstacle: AI compliance belongs to no one
Here I depart from the timeline, because the difficulty I encounter with clients is rarely the text of the AI Act. It is ownership.
I keep meeting organisations where responsibility for artificial intelligence sits in no department at all. It is scattered across legal, IT, security, procurement, marketing and the individual business lines, each assuming that another is handling it. What belongs to everyone belongs to nobody, and the consequence is that decisions with direct legal effect are taken by default rather than by design.
The second pattern is equally common and, in some respects, more deceptive, because it looks like a solution. AI compliance is parked entirely with the IT department. IT can map the systems and implement the technical controls, and that contribution is indispensable. However, IT teams are not equipped to determine whether a use case falls within Annex III, whether fine-tuning a model has converted the company from deployer into provider, whether a given Article 50 disclosure is legally adequate, or how a fundamental rights impact assessment should be conducted. Those are legal qualifications with immediate commercial consequences, and they are being taken, often unknowingly, by people who were never asked to take them.
This is precisely why 2 August 2026 exposes companies even though the high-risk obligations moved. Every obligation applying from today, whether the Article 50 disclosure, the provider classification question or the ability to answer a documentation request, requires that somebody with legal knowledge has examined the systems. Where AI compliance is ownerless, or purely technical, nobody has.
The same logic applies to the postponement. Additional months are worth very little to an organisation that has nobody accountable for using them. Time helps only where the work has an owner.
The question I would put to any board is therefore short: is anyone, by name, accountable for AI compliance in your organisation? If the answer takes more than a moment, that is the place to start. The structure that solves it is not complicated, and I described it in detail in How to Set Up an AI Committee in Your Company’s Governance Framework.
Six moves, and the date attached to each
Beyond the obligations dictated by the AI Act, companies need to govern the introduction of AI within their own organisation. The plan below is deliberately short, because a plan that cannot be remembered is not followed.
- MAP (now) – inventory every AI system in use, including the tools adopted without formal approval, with the owner and purpose of each.
- OWN (now) – identify roles and responsibilities across legal, IT, compliance, audit, risk management and the business lines. An AI committee with a clear mandate, an escalation path and documented decisions is no longer a luxury.
- CHECK (in force since 2 February 2025) – verify that no prohibited practice is in use, and establish whether customisation, retraining or rebranding has made you a provider.
- DISCLOSE (applies from 2 August 2026) – label chatbots, voice agents and AI-generated content.
- TRAIN (in force since 2 February 2025) – support the development of AI literacy among staff.
- PREPARE (2 December 2027) – begin the high-risk work now, together with supplier contracts addressing data protection and intellectual property, and internal policies setting the permitted scope of use and its limits.
Above all, document the decisions taken. A dated record of what was assessed and resolved is worth considerably more during an inquiry than an impeccable policy nobody applied. And do not treat the AI Act in isolation: data protection questions run in parallel, as the recent EDPB anonymisation guidelines show.
The message is clear
2 August 2026 is not the compliance cliff the market expected, and for most companies it is not a cliff at all. It is the moment enforcement begins, against a set of obligations that have been quietly accumulating since February 2025. For businesses that have someone accountable for artificial intelligence, this is manageable and, in several respects, a commercial opportunity. For those that do not, the postponement to December 2027 will pass exactly as the past eighteen months have passed.
Is anyone, by name, accountable for AI compliance in your organisation?
If the answer takes more than a moment, that is the place to start. Send me the list of the AI systems you use and I will tell you which of the six moves you actually need, and by when. A short call, no commitment.
Write to me at giulio.coraggio@dlapiper.com to book a 20-minute review
Read an infographic below that summarizes the contents of the article:


